{"investigation":{"slug":"moonwell-lending","entity_name":"Moonwell Lending","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Moonwell is a decentralized, non-custodial lending and borrowing protocol deployed on Base, Optimism, Moonbeam, and Moonriver, operating as a fork of Compound v2. The protocol has suffered at least five distinct security incidents between 2022 and 2026, resulting in combined losses and bad debt exceeding $5 million, including repeated oracle failures, a flash loan exploit, a near-successful governance attack, and an AI-assisted smart contract misconfiguration. Despite multiple audits by Halborn and Code4rena, the pattern of recurring vulnerabilities and the removal of its Immunefi bug bounty program in early 2025 have raised significant security concerns.","sections":[{"content":"Moonwell was founded in 2021 by Luke Youngblood, a former Coinbase and Amazon Web Services engineer, under the development company Lunar Labs. It operates as an open-source lending and borrowing protocol built primarily on the Compound v2 codebase with modifications for cross-chain functionality. The native governance token, WELL, grants holders voting rights on protocol parameters, supported assets, and upgrades. The protocol reached a peak TVL of approximately $400 million and, as of late 2025, managed over $234 million in assets across all supported chains, with approximately 78% of activity concentrated on the Base deployment. Moonwell has raised $10 million in a Strategic funding round in March 2022.","heading":"Overview","sources":[{"url":"https://nansen.ai/post/what-is-moonwell","name":"nansen.ai","type":"other","credibility":3},{"url":"https://messari.io/project/moonwell","name":"messari.io","type":"other","credibility":3},{"url":"https://news.bitcoin.com/lunar-labs-co-founder-luke-youngblood-talks-moonwell-artemis-and-over-collateralized-loans/","name":"news.bitcoin.com","type":"other","credibility":3},{"url":"https://www.coincarp.com/project/moonwell/","name":"coincarp.com","type":"other","credibility":3},{"url":"https://defillama.com/protocol/moonwell","name":"defillama.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 2, 2022, the Nomad cross-chain bridge — which Moonwell had integrated for Bitcoin, Ethereum, stablecoins, and altcoins on its Moonbeam deployment — was exploited for approximately $190.7 million. Bridged assets including USDC.mad, ETH.mad, and WBTC.mad lost their peg as a result. Users who had posted these assets as collateral on Moonwell were directly impacted, generating bad debt on the platform. Frax Finance-related bad debt on Moonwell's Moonbeam deployment was reported at approximately $2.9 million. The incident left the protocol carrying unresolved liabilities that persisted for years.","heading":"Security Incidents: Nomad Bridge Exposure (2022)","sources":[{"url":"https://cointelegraph.com/news/moonwell-bad-debt-recovery-plebiscite-draws-user-controversy","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/moonwells-bold-2-3m-plan-to-counter-frax-hack-debt-sparks-controversy/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://medium.com/@horatiolucas2/moonwell-finance-and-frax-finance-plan-to-appropriate-15m-users-assets-behind-a-controversial-dao-2912fcf62826","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In a governance plebiscite dated December 31, 2023, Moonwell proposed using approximately $2.3 million worth of dormant Nomad bridge collateral and protocol reserves to offset its outstanding Frax bad debt. The vote passed with approximately 98% approval from 57 participants. However, the proposal drew significant criticism from community members, most notably a user identified as Horatio Lucas, who alleged that the Nomad collateral in question belongs to individual owners and cannot be appropriated to offset protocol debt without their consent. Lucas argued that any vote allowing unaffected parties to decide the fate of Nomad users' assets constituted a form of misappropriation. Moonwell stated the plebiscite was non-binding and that a separate on-chain vote with a much higher quorum would be required before any assets were moved. No evidence of regulatory action related to this controversy has been found.","heading":"Governance Controversy: Frax Bad Debt Recovery (2023-2024)","sources":[{"url":"https://cointelegraph.com/news/moonwell-bad-debt-recovery-plebiscite-draws-user-controversy","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/moonwells-bold-2-3m-plan-to-counter-frax-hack-debt-sparks-controversy/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://medium.com/@horatiolucas2/moonwell-finance-and-frax-finance-plan-to-appropriate-15m-users-assets-behind-a-controversial-dao-2912fcf62826","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In December 2024, Moonwell's USDC lending contract on the Optimism network was exploited via a flash loan attack, resulting in a loss of approximately $320,000. The attacker deployed a malicious contract disguised as an mToken to gain unauthorized token approvals, then drained user funds from the lending pool. Stolen USDC was subsequently swapped for DAI, with the funds traced to an attacker-controlled wallet. The attacker's wallet was pre-funded through Tornado Cash on the Ethereum network. At the time of the incident, Moonwell had not released an official statement regarding user reimbursements.","heading":"Security Incident: Flash Loan Exploit, $320K (December 2024)","sources":[{"url":"https://coinmarketcap.com/academy/article/2ff106ab-e90e-47b4-8403-627e3802508d","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://coinedition.com/moonwell-defi-hit-by-320k-flash-loan-exploit-security-risks-highlighted/","name":"coinedition.com","type":"other","credibility":3},{"url":"https://bitcoinethereumnews.com/tech/moonwell-defi-exploited-in-320k-flash-loan-attack/","name":"bitcoinethereumnews.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 10, 2025, Moonwell lost approximately $1.7 million following a market dislocation event in which gaps between oracle prices and decentralized exchange prices allowed attackers to exploit liquidation mechanisms on its Base deployment. Security observers noted this as a failure mode common to lending protocols when oracle feeds lag during periods of high market volatility. The loss contributed to accumulated bad debt on the protocol.","heading":"Security Incident: Oracle Exploit, ~$1.7M (October 2025)","sources":[{"url":"https://www.mexc.com/en-PH/news/154021","name":"mexc.com","type":"other","credibility":3},{"url":"https://coinfomania.com/moonwell-oracle-exploit-base-optimism/","name":"coinfomania.com","type":"other","credibility":3},{"url":"https://99bitcoins.com/news/altcoins/moonwell-hack-1m-lost-after-chainlink-flaw-well-crypto-slumps-to-2025-lows/","name":"99bitcoins.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On November 4, 2025, Moonwell suffered its most damaging single incident to that point. A Chainlink oracle malfunctioned and erroneously reported a single wrsETH (wrapped restaked ETH) token as priced at approximately $5.8 billion (roughly 1.65 million ETH). An attacker exploited this discrepancy within 30 seconds by depositing minimal wrsETH collateral and obtaining massive flash loans, repeating the process across multiple transactions on both Base and Optimism to drain approximately 295 ETH (roughly $1 million). Beyond the direct theft, the exploit left Moonwell with approximately $3.7 million in bad debt. The WELL governance token fell approximately 13.5% within a single day. Security analysts noted the oracle configuration included 'archaic heartbeat intervals and broad deviation thresholds' allowing large price deviations before triggering updates. This was widely reported as Moonwell's fourth major incident in approximately three years. Notably, Moonwell had removed its Immunefi bug bounty program in early 2025, prior to this and other subsequent exploits.","heading":"Security Incident: Chainlink Oracle Malfunction, ~$1M + $3.7M Bad Debt (November 2025)","sources":[{"url":"https://www.web3isgoinggreat.com/?id=moonwell-oracle-malfunction","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-moonwell-hack-november-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://coinfomania.com/moonwell-oracle-exploit-base-optimism/","name":"coinfomania.com","type":"other","credibility":3},{"url":"https://en.coinotag.com/moonwells-1m-oracle-exploit-raises-defi-security-concerns-well-token-falls-12/","name":"en.coinotag.com","type":"other","credibility":3},{"url":"https://99bitcoins.com/news/altcoins/moonwell-hack-1m-lost-after-chainlink-flaw-well-crypto-slumps-to-2025-lows/","name":"99bitcoins.com","type":"other","credibility":3},{"url":"https://ambcrypto.com/chainlink-oracle-glitch-costs-moonwell-1m-as-defi-suffers-another-exploit/","name":"ambcrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 15, 2026, Moonwell executed governance proposal MIP-X43, deploying Chainlink OEV wrapper contracts across its core markets on Base and Optimism. A misconfiguration in one oracle contract caused the USD price of Coinbase Wrapped Staked ETH (cbETH) to be derived solely from the raw cbETH/ETH exchange rate rather than multiplying it by the ETH/USD price feed. As a result, cbETH was valued at approximately $1.12 instead of its actual price of roughly $2,200 — a 99.9% undervaluation. Liquidation bots immediately began targeting cbETH collateral positions; liquidators repaid approximately $1 of debt to seize 1,096.317 cbETH worth thousands of dollars each. Separately, opportunistic users supplied minimal collateral to massively overborrow cbETH at the distorted price. Total bad debt accumulated was approximately $1.78 million. Risk managers responded by reducing cbETH borrow and supply caps to 0.01, limiting further damage. Multiple code commits involved in the MIP-X43 governance proposal were co-authored by Anthropic's Claude Opus 4.6, visible in GitHub pull requests. Security auditor Pashov publicly stated the vulnerability could have been caught with a proper integration test. Experts noted this incident heightened scrutiny of AI-assisted smart contract development practices, warning that AI-generated code requires strict version control, peer review, and rigorous testing before deployment in high-risk financial applications.","heading":"Security Incident: AI-Assisted Oracle Misconfiguration, $1.78M Bad Debt (February 2026)","sources":[{"url":"https://decrypt.co/358374/oracle-error-leaves-defi-lender-moonwell-1-8-million-bad-debt","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/moonwell-exploit-cbeth-oracle-misprice-ai-commits-testing-audits","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/claude-moonwell-smart-contract-exploit/","name":"cryptopolitan.com","type":"other","credibility":3},{"url":"https://financefeeds.com/moonwell-exploited-for-1-78-million-after-cbeth-oracle-mispricing/","name":"financefeeds.com","type":"other","credibility":3},{"url":"https://crypto.news/moonwells-ai-coded-oracle-glitch-misprices-cbeth-at-1-drains-1-78m/","name":"crypto.news","type":"other","credibility":3},{"url":"https://btcusa.com/moonwell-hack-1-78m-exploit-linked-to-ai-generated-oracle-bug/","name":"btcusa.com","type":"other","credibility":3}],"severity":"medium"},{"content":"In March 2026, an unknown attacker launched a governance attack against Moonwell's Moonriver deployment. For an outlay of approximately $1,808 (1,600 MOVR), the attacker purchased 40.17 million MFAM governance tokens from the SolarBeam DEX, submitted a malicious governance proposal, and voted it past quorum — all within approximately 11 minutes. The proposal was designed to transfer administrative control of seven lending markets, the comptroller, and the oracle to an attacker-controlled contract, placing approximately $1.08 million in user assets at risk. The proposal contained pre-configured transactions intended to automate the draining of protocol liquidity. Community voting ultimately opposed the proposal (approximately 66.7% against), and Moonwell's 'Break Glass Guardian' emergency multisig veto mechanism was available as a final safeguard. The attack highlighted critical weaknesses in the protocol's governance design, including low token acquisition costs required to reach quorum on the lower-TVL Moonriver deployment.","heading":"Security Incident: Governance Attack (March 2026)","sources":[{"url":"https://crypto.news/moonwell-hit-by-governance-attack-1-08m-at-risk-for-1800-spend/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=moonwell-governance-attack","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://www.dlnews.com/articles/defi/attacker-spends-less-two-grand-to-hold-crypto-project-hostage/","name":"dlnews.com","type":"other","credibility":3},{"url":"https://www.kucoin.com/news/flash/defi-lending-protocol-moonwell-faces-governance-attack-on-moonriver","name":"kucoin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Moonwell engaged Halborn for multiple smart contract security audits beginning in early 2022, including audits of governance and timelock contracts, cross-chain governance, EVM contracts, and various feature-specific deployments. A $100,000 USDC Code4rena competitive audit in July 2023 yielded 17 medium severity vulnerabilities and 56 low/informational findings, with no high severity issues identified at the time. In early 2025, Moonwell removed its Immunefi bug bounty program and proposed migrating to Code4rena's bug bounty platform, citing a preference for quality over quantity in vulnerability submissions. The timing of this removal, occurring before the November 2025 oracle exploit and the February 2026 oracle misconfiguration, drew criticism from security observers who noted that active bug bounty programs provide financial incentives for responsible disclosure of critical vulnerabilities. As of the governance attack in March 2026, the protocol maintained an emergency 'Break Glass Guardian' multisig as a backstop against severe governance failures.","heading":"Bug Bounty and Security Posture","sources":[{"url":"https://www.halborn.com/audits/moonwell/smart-contract-assessment-409b83","name":"halborn.com","type":"other","credibility":3},{"url":"https://code4rena.com/audits/2023-07-moonwell","name":"code4rena.com","type":"other","credibility":3},{"url":"https://forum.moonwell.fi/t/migrate-moonwells-bug-bounty-program-provider-from-immunefi-to-code4rena/1386","name":"forum.moonwell.fi","type":"other","credibility":3},{"url":"https://ambcrypto.com/chainlink-oracle-glitch-costs-moonwell-1m-as-defi-suffers-another-exploit/","name":"ambcrypto.com","type":"other","credibility":3},{"url":"https://docs.moonwell.fi/moonwell/protocol-information/audits","name":"docs.moonwell.fi","type":"other","credibility":3}],"severity":"medium"},{"content":"No SEC enforcement actions, CFTC actions, DOJ proceedings, or OFAC sanctions specifically targeting Moonwell, Lunar Labs, or founder Luke Youngblood have been identified in publicly available records as of the time of this investigation. The protocol operates as a decentralized autonomous organization (DAO) governed by WELL token holders. No court filings or formal regulatory charges have been located.","heading":"Regulatory and Legal Status","sources":[{"url":"https://docs.moonwell.fi/moonwell","name":"docs.moonwell.fi","type":"other","credibility":3},{"url":"https://messari.io/project/moonwell","name":"messari.io","type":"other","credibility":3}],"severity":"medium"},{"content":"As of early 2026, Moonwell continues to operate across Base, Optimism, Moonbeam, and Moonriver. The DAO approved governance proposal MIP-X49 on April 6, 2026, implementing fixes to the protocol's Wormhole V3 cross-chain integration following a March 2026 upgrade. The protocol continues to carry unresolved bad debt from prior exploits. The cumulative pattern of five major security incidents in under four years — involving oracle failures, flash loan attacks, an AI-assisted code misconfiguration, and a governance attack — alongside the removal of a bug bounty program, represents a materially elevated risk profile relative to comparable DeFi lending protocols.","heading":"Current Status","sources":[{"url":"https://defillama.com/protocol/moonwell","name":"defillama.com","type":"other","credibility":3},{"url":"https://www.bitget.com/academy/moonwell-defi-guide","name":"bitget.com","type":"other","credibility":3},{"url":"https://x.com/QuillAudits_AI/status/1985654917898649840","name":"x.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021","event":"Moonwell founded by Luke Youngblood under Lunar Labs; built as a Compound v2 fork targeting Moonbeam network","source":"","date_original":"2021-01-01"},{"date":"2022-03-17","event":"Moonwell raises $10 million in Strategic funding round","source":""},{"date":"2022-08-02","event":"Nomad bridge exploited for $190.7 million; Moonwell's Moonbeam deployment suffers collateral losses and bad debt including approximately $2.9 million in Frax-related bad debt","source":""},{"date":"2023-07-24","event":"Code4rena competitive audit identifies 17 medium severity vulnerabilities and 56 low/informational issues; no critical or high severity findings","source":""},{"date":"2023-12-31","event":"Non-binding governance plebiscite passes 98% in favor of using Nomad collateral and protocol reserves to address Frax bad debt, drawing community controversy over asset appropriation","source":""},{"date":"2024-12","event":"Flash loan exploit on Optimism USDC market drains approximately $320,000 via a malicious mToken contract; stolen funds swapped to DAI","source":"","date_original":"2024-12-01"},{"date":"2025-02","event":"Moonwell removes its Immunefi bug bounty program; proposes migration to Code4rena bug bounty platform","source":"","date_original":"2025-02-01"},{"date":"2025-10-10","event":"Oracle-DEX price gap during market volatility allows exploitation of liquidation mechanisms on Base deployment; approximately $1.7 million lost","source":""},{"date":"2025-11-04","event":"Chainlink oracle malfunction misprices wrsETH at $5.8 billion; attacker drains approximately $1 million (295 ETH) within 30 seconds; $3.7 million in bad debt accrues; WELL token drops ~13.5%","source":""},{"date":"2026-02-15","event":"Governance proposal MIP-X43 deploys misconfigured Chainlink OEV oracle; cbETH mispriced at ~$1.12 instead of ~$2,200; $1.78 million in bad debt generated; AI-assisted code co-authored by Claude Opus 4.6 implicated","source":""},{"date":"2026-03-24","event":"Governance attack on Moonriver deployment: attacker spends $1,808 to acquire voting tokens, submits malicious proposal, reaches quorum in ~11 minutes; $1.08 million in assets placed at risk; community votes defeated the proposal","source":""},{"date":"2026-04-06","event":"DAO approves MIP-X49, implementing fixes to Wormhole V3 cross-chain integration following March 2026 upgrade (MIP-X48)","source":""}],"sources_used":[{"url":"https://nansen.ai/post/what-is-moonwell","name":"nansen.ai","type":"other","archive_url":"http://web.archive.org/web/20260516115816/https://nansen.ai/post/what-is-moonwell","credibility":3,"archive_timestamp":"2026-05-16T11:58:16+00:00"},{"url":"https://messari.io/project/moonwell","name":"messari.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://news.bitcoin.com/lunar-labs-co-founder-luke-youngblood-talks-moonwell-artemis-and-over-collateralized-loans/","name":"news.bitcoin.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.coincarp.com/project/moonwell/","name":"coincarp.com","type":"other","archive_url":"https://web.archive.org/web/20260829084644/https://www.coincarp.com/project/moonwell/","credibility":3,"archive_timestamp":"2026-08-29T08:46:44+00:00"},{"url":"https://defillama.com/protocol/moonwell","name":"defillama.com","type":"other","archive_url":"http://web.archive.org/web/20250911122553/https://defillama.com/protocol/moonwell","credibility":3,"archive_timestamp":"2025-09-11T12:25:53+00:00"},{"url":"https://cointelegraph.com/news/moonwell-bad-debt-recovery-plebiscite-draws-user-controversy","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260420190949/https://cointelegraph.com/news/moonwell-bad-debt-recovery-plebiscite-draws-user-controversy","credibility":3,"archive_timestamp":"2026-04-20T19:09:49+00:00"},{"url":"https://cryptonews.com/news/moonwells-bold-2-3m-plan-to-counter-frax-hack-debt-sparks-controversy/","name":"cryptonews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://medium.com/@horatiolucas2/moonwell-finance-and-frax-finance-plan-to-appropriate-15m-users-assets-behind-a-controversial-dao-2912fcf62826","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinmarketcap.com/academy/article/2ff106ab-e90e-47b4-8403-627e3802508d","name":"coinmarketcap.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinedition.com/moonwell-defi-hit-by-320k-flash-loan-exploit-security-risks-highlighted/","name":"coinedition.com","type":"other","archive_url":"https://web.archive.org/web/20260829225151/https://coinedition.com/moonwell-defi-hit-by-320k-flash-loan-exploit-security-risks-highlighted/","credibility":3,"archive_timestamp":"2026-08-29T22:51:51+00:00"},{"url":"https://bitcoinethereumnews.com/tech/moonwell-defi-exploited-in-320k-flash-loan-attack/","name":"bitcoinethereumnews.com","type":"other","archive_url":"http://web.archive.org/web/20260829023902/https://bitcoinethereumnews.com/tech/moonwell-defi-exploited-in-320k-flash-loan-attack/","credibility":3,"archive_timestamp":"2026-08-29T02:39:02+00:00"},{"url":"https://www.mexc.com/en-PH/news/154021","name":"mexc.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinfomania.com/moonwell-oracle-exploit-base-optimism/","name":"coinfomania.com","type":"other","archive_url":"http://web.archive.org/web/20251116131005/https://coinfomania.com/moonwell-oracle-exploit-base-optimism/","credibility":3,"archive_timestamp":"2025-11-16T13:10:05+00:00"},{"url":"https://99bitcoins.com/news/altcoins/moonwell-hack-1m-lost-after-chainlink-flaw-well-crypto-slumps-to-2025-lows/","name":"99bitcoins.com","type":"other","archive_url":"http://web.archive.org/web/20251114124018/https://99bitcoins.com/news/altcoins/moonwell-hack-1m-lost-after-chainlink-flaw-well-crypto-slumps-to-2025-lows/","credibility":3,"archive_timestamp":"2025-11-14T12:40:18+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=moonwell-oracle-malfunction","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260816110204/https://www.web3isgoinggreat.com/?id=moonwell-oracle-malfunction","credibility":3,"archive_timestamp":"2026-08-16T11:02:04+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-moonwell-hack-november-2025","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260109140245/https://www.halborn.com/blog/post/explained-the-moonwell-hack-november-2025","credibility":3,"archive_timestamp":"2026-01-09T14:02:45+00:00"},{"url":"https://en.coinotag.com/moonwells-1m-oracle-exploit-raises-defi-security-concerns-well-token-falls-12/","name":"en.coinotag.com","type":"other","archive_url":"http://web.archive.org/web/20251118211105/https://en.coinotag.com/moonwells-1m-oracle-exploit-raises-defi-security-concerns-well-token-falls-12","credibility":3,"archive_timestamp":"2025-11-18T21:11:05+00:00"},{"url":"https://ambcrypto.com/chainlink-oracle-glitch-costs-moonwell-1m-as-defi-suffers-another-exploit/","name":"ambcrypto.com","type":"other","archive_url":"http://web.archive.org/web/20251104203551/https://ambcrypto.com/chainlink-oracle-glitch-costs-moonwell-1m-as-defi-suffers-another-exploit/","credibility":3,"archive_timestamp":"2025-11-04T20:35:51+00:00"},{"url":"https://decrypt.co/358374/oracle-error-leaves-defi-lender-moonwell-1-8-million-bad-debt","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260606232754/https://decrypt.co/358374/oracle-error-leaves-defi-lender-moonwell-1-8-million-bad-debt","credibility":3,"archive_timestamp":"2026-06-06T23:27:54+00:00"},{"url":"https://cointelegraph.com/news/moonwell-exploit-cbeth-oracle-misprice-ai-commits-testing-audits","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260811070715/https://cointelegraph.com/news/moonwell-exploit-cbeth-oracle-misprice-ai-commits-testing-audits","credibility":3,"archive_timestamp":"2026-08-11T07:07:15+00:00"},{"url":"https://www.cryptopolitan.com/claude-moonwell-smart-contract-exploit/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20260311162646/https://www.cryptopolitan.com/claude-moonwell-smart-contract-exploit/","credibility":3,"archive_timestamp":"2026-03-11T16:26:46+00:00"},{"url":"https://financefeeds.com/moonwell-exploited-for-1-78-million-after-cbeth-oracle-mispricing/","name":"financefeeds.com","type":"other","archive_url":"https://web.archive.org/web/20260829225918/https://financefeeds.com/moonwell-exploited-for-1-78-million-after-cbeth-oracle-mispricing/","credibility":3,"archive_timestamp":"2026-08-29T22:59:18+00:00"},{"url":"https://crypto.news/moonwells-ai-coded-oracle-glitch-misprices-cbeth-at-1-drains-1-78m/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260313075543/https://crypto.news/moonwells-ai-coded-oracle-glitch-misprices-cbeth-at-1-drains-1-78m/","credibility":3,"archive_timestamp":"2026-03-13T07:55:43+00:00"},{"url":"https://btcusa.com/moonwell-hack-1-78m-exploit-linked-to-ai-generated-oracle-bug/","name":"btcusa.com","type":"other","archive_url":"http://web.archive.org/web/20260829024949/https://btcusa.com/moonwell-hack-1-78m-exploit-linked-to-ai-generated-oracle-bug/","credibility":3,"archive_timestamp":"2026-08-29T02:49:49+00:00"},{"url":"https://crypto.news/moonwell-hit-by-governance-attack-1-08m-at-risk-for-1800-spend/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260422110945/https://crypto.news/moonwell-hit-by-governance-attack-1-08m-at-risk-for-1800-spend/","credibility":3,"archive_timestamp":"2026-04-22T11:09:45+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=moonwell-governance-attack","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260731061216/https://www.web3isgoinggreat.com/?id=moonwell-governance-attack","credibility":3,"archive_timestamp":"2026-07-31T06:12:16+00:00"},{"url":"https://www.dlnews.com/articles/defi/attacker-spends-less-two-grand-to-hold-crypto-project-hostage/","name":"dlnews.com","type":"other","archive_url":"http://web.archive.org/web/20260617073926/https://www.dlnews.com/articles/defi/attacker-spends-less-two-grand-to-hold-crypto-project-hostage/","credibility":3,"archive_timestamp":"2026-06-17T07:39:26+00:00"},{"url":"https://www.kucoin.com/news/flash/defi-lending-protocol-moonwell-faces-governance-attack-on-moonriver","name":"kucoin.com","type":"other","archive_url":"https://web.archive.org/web/20260829090402/https://www.kucoin.com/news/flash/defi-lending-protocol-moonwell-faces-governance-attack-on-moonriver","credibility":3,"archive_timestamp":"2026-08-29T09:04:02+00:00"},{"url":"https://www.halborn.com/audits/moonwell/smart-contract-assessment-409b83","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260414122135/https://www.halborn.com/audits/moonwell/smart-contract-assessment-409b83","credibility":3,"archive_timestamp":"2026-04-14T12:21:35+00:00"},{"url":"https://code4rena.com/audits/2023-07-moonwell","name":"code4rena.com","type":"other","archive_url":"http://web.archive.org/web/20260417131410/https://code4rena.com/audits/2023-07-moonwell","credibility":3,"archive_timestamp":"2026-04-17T13:14:10+00:00"},{"url":"https://forum.moonwell.fi/t/migrate-moonwells-bug-bounty-program-provider-from-immunefi-to-code4rena/1386","name":"forum.moonwell.fi","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://docs.moonwell.fi/moonwell/protocol-information/audits","name":"docs.moonwell.fi","type":"other","archive_url":"http://web.archive.org/web/20260718173135/https://docs.moonwell.fi/moonwell/protocol-information/audits","credibility":3,"archive_timestamp":"2026-07-18T17:31:35+00:00"},{"url":"https://docs.moonwell.fi/moonwell","name":"docs.moonwell.fi","type":"other","archive_url":"http://web.archive.org/web/20260718173143/https://docs.moonwell.fi/moonwell","credibility":3,"archive_timestamp":"2026-07-18T17:31:43+00:00"},{"url":"https://www.bitget.com/academy/moonwell-defi-guide","name":"bitget.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://x.com/QuillAudits_AI/status/1985654917898649840","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:20.468866+00:00","updated_at":"2026-08-30T03:54:59.058934+00:00"}}